Re: IPFilter on Solaris

This is a discussion on Re: IPFilter on Solaris within the IPFilter forums, part of the System Security and Security Related category; >Even though I don't work for them I have some idea. I got my >Ultra20 in order ...


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 12-15-2006
a b
 
Posts: n/a
Default Re: IPFilter on Solaris

>Even though I don't work for them I have some idea. I got my
>Ultra20 in order to learn about things about Solaris since I
>am now in a group at work that uses a lot of Solaris. It has been
>more than a year and my self education process is slow. IPfilter
>in particular is an area where I am stalled. I would love to set
>it up to do NAT routing as I have already been doing for years with
>SuSE linux. So far I have only succeeded in getting it running
>with one simple pass all rule.


IPFilter works "the other way" -- normally one would expect the firewall to
match on a rule and perform some action, like other firewalls do. However,
unless one specifies "quick" as part of the rule, IPFilter will match on the
"closest match" which is quite often the last rule pertaining to something.
Confusing? Well, you're not the only one; this confuses a lot of people new
to IPFilter.

So if you want IPFilter to behave the way other firewalls do, use the
keyword "quick" as that short circuits further mathing and immediately
performs whatever the rule tells him (IPFilter) to do.

As far as documentation, when I was starting with IPFilter years ago, I
found the "IPFilter HOWTO" (Google!) to be an excellent introduction.

For all the nitty-gritty details, man pages are also quite good, especially
if you're used to absorbing man page material very quickly (gotta love the
standardized format of man pages!)

__________________________________________________ _______________
Don't just search. Find. Check out the new MSN Search!
http://search.msn.click-url.com/go/o...ave/direct/01/

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 04:41 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0